2023-11-15 02:08:22 +01:00
|
|
|
import { AlbumResponseDto, IAssetRepository, LoginResponseDto, SharedLinkResponseDto } from '@app/domain';
|
|
|
|
import { SharedLinkController } from '@app/immich';
|
|
|
|
import { SharedLinkType } from '@app/infra/entities';
|
|
|
|
import { INestApplication } from '@nestjs/common';
|
2023-09-11 17:56:38 +02:00
|
|
|
import { api } from '@test/api';
|
2023-11-15 02:31:06 +01:00
|
|
|
import { errorStub, userDto, uuidStub } from '@test/fixtures';
|
2023-11-15 02:08:22 +01:00
|
|
|
import { testApp } from '@test/test-utils';
|
|
|
|
import { DateTime } from 'luxon';
|
2023-09-11 17:56:38 +02:00
|
|
|
import request from 'supertest';
|
|
|
|
|
2023-11-15 02:08:22 +01:00
|
|
|
const today = new Date();
|
|
|
|
|
|
|
|
describe(`${SharedLinkController.name} (e2e)`, () => {
|
2023-09-11 17:56:38 +02:00
|
|
|
let server: any;
|
2023-10-14 03:46:30 +02:00
|
|
|
let admin: LoginResponseDto;
|
2023-09-11 17:56:38 +02:00
|
|
|
let user1: LoginResponseDto;
|
2023-11-15 02:08:22 +01:00
|
|
|
let user2: LoginResponseDto;
|
2023-09-11 17:56:38 +02:00
|
|
|
let album: AlbumResponseDto;
|
2023-11-15 02:08:22 +01:00
|
|
|
let metadataAlbum: AlbumResponseDto;
|
|
|
|
let deletedAlbum: AlbumResponseDto;
|
2023-09-11 17:56:38 +02:00
|
|
|
let sharedLink: SharedLinkResponseDto;
|
2023-11-15 02:08:22 +01:00
|
|
|
let linkWithDeletedAlbum: SharedLinkResponseDto;
|
|
|
|
let linkWithPassword: SharedLinkResponseDto;
|
|
|
|
let linkWithMetadata: SharedLinkResponseDto;
|
|
|
|
let linkWithoutMetadata: SharedLinkResponseDto;
|
|
|
|
let app: INestApplication<any>;
|
2023-09-11 17:56:38 +02:00
|
|
|
|
|
|
|
beforeAll(async () => {
|
2023-11-15 02:08:22 +01:00
|
|
|
[server, app] = await testApp.create();
|
|
|
|
const assetRepository = app.get<IAssetRepository>(IAssetRepository);
|
2023-10-19 00:02:42 +02:00
|
|
|
|
2023-11-15 02:08:22 +01:00
|
|
|
await testApp.reset();
|
2023-09-11 17:56:38 +02:00
|
|
|
await api.authApi.adminSignUp(server);
|
2023-10-14 03:46:30 +02:00
|
|
|
admin = await api.authApi.adminLogin(server);
|
2023-09-11 17:56:38 +02:00
|
|
|
|
2023-11-15 02:08:22 +01:00
|
|
|
await Promise.all([
|
2023-11-15 02:31:06 +01:00
|
|
|
api.userApi.create(server, admin.accessToken, userDto.user1),
|
|
|
|
api.userApi.create(server, admin.accessToken, userDto.user2),
|
2023-11-15 02:08:22 +01:00
|
|
|
]);
|
|
|
|
|
|
|
|
[user1, user2] = await Promise.all([
|
2023-11-15 02:31:06 +01:00
|
|
|
api.authApi.login(server, userDto.user1),
|
|
|
|
api.authApi.login(server, userDto.user2),
|
2023-11-15 02:08:22 +01:00
|
|
|
]);
|
|
|
|
|
|
|
|
const asset = await api.assetApi.create(server, user1.accessToken, {
|
|
|
|
fileCreatedAt: today,
|
|
|
|
fileModifiedAt: today,
|
|
|
|
deviceId: 'test',
|
|
|
|
deviceAssetId: 'test',
|
|
|
|
});
|
2023-09-11 17:56:38 +02:00
|
|
|
|
2023-11-15 02:08:22 +01:00
|
|
|
await assetRepository.upsertExif({
|
|
|
|
assetId: asset.id,
|
|
|
|
longitude: -108.400968333333,
|
|
|
|
latitude: 39.115,
|
|
|
|
orientation: '1',
|
|
|
|
dateTimeOriginal: DateTime.fromISO('2022-01-10T19:15:44.310Z').toJSDate(),
|
|
|
|
timeZone: 'UTC-4',
|
|
|
|
state: 'Mesa County, Colorado',
|
|
|
|
country: 'United States of America',
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
2023-11-15 02:08:22 +01:00
|
|
|
|
|
|
|
[album, deletedAlbum, metadataAlbum] = await Promise.all([
|
|
|
|
api.albumApi.create(server, user1.accessToken, { albumName: 'album' }),
|
|
|
|
api.albumApi.create(server, user2.accessToken, { albumName: 'deleted album' }),
|
|
|
|
api.albumApi.create(server, user1.accessToken, { albumName: 'metadata album', assetIds: [asset.id] }),
|
|
|
|
]);
|
|
|
|
|
|
|
|
[linkWithDeletedAlbum, sharedLink, linkWithPassword, linkWithMetadata, linkWithoutMetadata] = await Promise.all([
|
|
|
|
api.sharedLinkApi.create(server, user2.accessToken, {
|
|
|
|
type: SharedLinkType.ALBUM,
|
|
|
|
albumId: deletedAlbum.id,
|
|
|
|
}),
|
|
|
|
api.sharedLinkApi.create(server, user1.accessToken, {
|
|
|
|
type: SharedLinkType.ALBUM,
|
|
|
|
albumId: album.id,
|
|
|
|
}),
|
|
|
|
api.sharedLinkApi.create(server, user1.accessToken, {
|
|
|
|
type: SharedLinkType.ALBUM,
|
|
|
|
albumId: album.id,
|
|
|
|
password: 'foo',
|
|
|
|
}),
|
|
|
|
api.sharedLinkApi.create(server, user1.accessToken, {
|
|
|
|
type: SharedLinkType.ALBUM,
|
|
|
|
albumId: metadataAlbum.id,
|
|
|
|
showMetadata: true,
|
|
|
|
}),
|
|
|
|
api.sharedLinkApi.create(server, user1.accessToken, {
|
|
|
|
type: SharedLinkType.ALBUM,
|
|
|
|
albumId: metadataAlbum.id,
|
|
|
|
showMetadata: false,
|
|
|
|
}),
|
|
|
|
]);
|
|
|
|
|
|
|
|
await api.userApi.delete(server, admin.accessToken, user2.userId);
|
|
|
|
});
|
|
|
|
|
|
|
|
afterAll(async () => {
|
|
|
|
await testApp.teardown();
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
|
|
|
describe('GET /shared-link', () => {
|
|
|
|
it('should require authentication', async () => {
|
|
|
|
const { status, body } = await request(server).get('/shared-link');
|
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.unauthorized);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should get all shared links created by user', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.get('/shared-link')
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`);
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
2023-11-15 02:08:22 +01:00
|
|
|
expect(body).toHaveLength(4);
|
|
|
|
expect(body).toEqual(
|
|
|
|
expect.arrayContaining([
|
|
|
|
expect.objectContaining({ id: sharedLink.id }),
|
|
|
|
expect.objectContaining({ id: linkWithPassword.id }),
|
|
|
|
expect.objectContaining({ id: linkWithMetadata.id }),
|
|
|
|
expect.objectContaining({ id: linkWithoutMetadata.id }),
|
|
|
|
]),
|
|
|
|
);
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
|
|
|
it('should not get shared links created by other users', async () => {
|
2023-10-14 03:46:30 +02:00
|
|
|
const { status, body } = await request(server)
|
|
|
|
.get('/shared-link')
|
|
|
|
.set('Authorization', `Bearer ${admin.accessToken}`);
|
2023-09-11 17:56:38 +02:00
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
expect(body).toEqual([]);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
describe('GET /shared-link/me', () => {
|
|
|
|
it('should not require admin authentication', async () => {
|
2023-10-14 03:46:30 +02:00
|
|
|
const { status } = await request(server)
|
|
|
|
.get('/shared-link/me')
|
|
|
|
.set('Authorization', `Bearer ${admin.accessToken}`);
|
2023-09-11 17:56:38 +02:00
|
|
|
|
|
|
|
expect(status).toBe(403);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should get data for correct shared link', async () => {
|
|
|
|
const { status, body } = await request(server).get('/shared-link/me').query({ key: sharedLink.key });
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
2023-11-15 02:08:22 +01:00
|
|
|
expect(body).toEqual(
|
|
|
|
expect.objectContaining({
|
|
|
|
album,
|
|
|
|
userId: user1.userId,
|
|
|
|
type: SharedLinkType.ALBUM,
|
|
|
|
}),
|
|
|
|
);
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
|
|
|
it('should return unauthorized for incorrect shared link', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.get('/shared-link/me')
|
|
|
|
.query({ key: sharedLink.key + 'foo' });
|
|
|
|
|
|
|
|
expect(status).toBe(401);
|
2023-09-18 17:56:50 +02:00
|
|
|
expect(body).toEqual(errorStub.invalidShareKey);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should return unauthorized if target has been soft deleted', async () => {
|
2023-11-15 02:08:22 +01:00
|
|
|
const { status, body } = await request(server).get('/shared-link/me').query({ key: linkWithDeletedAlbum.key });
|
2023-09-18 17:56:50 +02:00
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.invalidShareKey);
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
2023-10-29 02:35:38 +01:00
|
|
|
|
|
|
|
it('should return unauthorized for password protected link', async () => {
|
2023-11-15 02:08:22 +01:00
|
|
|
const { status, body } = await request(server).get('/shared-link/me').query({ key: linkWithPassword.key });
|
2023-10-29 02:35:38 +01:00
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.invalidSharePassword);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should get data for correct password protected link', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.get('/shared-link/me')
|
2023-11-15 02:08:22 +01:00
|
|
|
.query({ key: linkWithPassword.key, password: 'foo' });
|
2023-10-29 02:35:38 +01:00
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
expect(body).toEqual(expect.objectContaining({ album, userId: user1.userId, type: SharedLinkType.ALBUM }));
|
|
|
|
});
|
2023-11-15 02:08:22 +01:00
|
|
|
|
|
|
|
it('should return metadata for album shared link', async () => {
|
|
|
|
const { status, body } = await request(server).get('/shared-link/me').query({ key: linkWithMetadata.key });
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
expect(body.assets).toHaveLength(1);
|
|
|
|
expect(body.assets[0]).toEqual(
|
|
|
|
expect.objectContaining({
|
|
|
|
originalFileName: 'example',
|
|
|
|
localDateTime: expect.any(String),
|
|
|
|
fileCreatedAt: expect.any(String),
|
|
|
|
exifInfo: expect.objectContaining({
|
|
|
|
longitude: -108.400968333333,
|
|
|
|
latitude: 39.115,
|
|
|
|
orientation: '1',
|
|
|
|
dateTimeOriginal: expect.any(String),
|
|
|
|
timeZone: 'UTC-4',
|
|
|
|
state: 'Mesa County, Colorado',
|
|
|
|
country: 'United States of America',
|
|
|
|
}),
|
|
|
|
}),
|
|
|
|
);
|
|
|
|
expect(body.album).toBeDefined();
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should not return metadata for album shared link without metadata', async () => {
|
|
|
|
const { status, body } = await request(server).get('/shared-link/me').query({ key: linkWithoutMetadata.key });
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
expect(body.assets).toHaveLength(1);
|
|
|
|
expect(body.album).toBeDefined();
|
|
|
|
|
|
|
|
const asset = body.assets[0];
|
|
|
|
expect(asset).not.toHaveProperty('exifInfo');
|
|
|
|
expect(asset).not.toHaveProperty('fileCreatedAt');
|
|
|
|
expect(asset).not.toHaveProperty('originalFilename');
|
|
|
|
expect(asset).not.toHaveProperty('originalPath');
|
|
|
|
});
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
|
|
|
describe('GET /shared-link/:id', () => {
|
|
|
|
it('should require authentication', async () => {
|
|
|
|
const { status, body } = await request(server).get(`/shared-link/${sharedLink.id}`);
|
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.unauthorized);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should get shared link by id', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.get(`/shared-link/${sharedLink.id}`)
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`);
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
expect(body).toEqual(expect.objectContaining({ album, userId: user1.userId, type: SharedLinkType.ALBUM }));
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should not get shared link by id if user has not created the link or it does not exist', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.get(`/shared-link/${sharedLink.id}`)
|
2023-10-14 03:46:30 +02:00
|
|
|
.set('Authorization', `Bearer ${admin.accessToken}`);
|
2023-09-11 17:56:38 +02:00
|
|
|
|
|
|
|
expect(status).toBe(400);
|
|
|
|
expect(body).toEqual(expect.objectContaining({ message: 'Shared link not found' }));
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
describe('POST /shared-link', () => {
|
|
|
|
it('should require authentication', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.post('/shared-link')
|
|
|
|
.send({ type: SharedLinkType.ALBUM, albumId: uuidStub.notFound });
|
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.unauthorized);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should require a type and the correspondent asset/album id', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.post('/shared-link')
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`);
|
|
|
|
|
|
|
|
expect(status).toBe(400);
|
2023-09-20 13:16:33 +02:00
|
|
|
expect(body).toEqual(errorStub.badRequest());
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
|
|
|
it('should require an asset/album id', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.post('/shared-link')
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`)
|
|
|
|
.send({ type: SharedLinkType.ALBUM });
|
|
|
|
|
|
|
|
expect(status).toBe(400);
|
|
|
|
expect(body).toEqual(expect.objectContaining({ message: 'Invalid albumId' }));
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should require a valid asset id', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.post('/shared-link')
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`)
|
|
|
|
.send({ type: SharedLinkType.INDIVIDUAL, assetId: uuidStub.notFound });
|
|
|
|
|
|
|
|
expect(status).toBe(400);
|
|
|
|
expect(body).toEqual(expect.objectContaining({ message: 'Invalid assetIds' }));
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should create a shared link', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.post('/shared-link')
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`)
|
|
|
|
.send({ type: SharedLinkType.ALBUM, albumId: album.id });
|
|
|
|
|
|
|
|
expect(status).toBe(201);
|
|
|
|
expect(body).toEqual(expect.objectContaining({ type: SharedLinkType.ALBUM, userId: user1.userId }));
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
describe('PATCH /shared-link/:id', () => {
|
|
|
|
it('should require authentication', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.patch(`/shared-link/${sharedLink.id}`)
|
|
|
|
.send({ description: 'foo' });
|
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.unauthorized);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should fail if invalid link', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.patch(`/shared-link/${uuidStub.notFound}`)
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`)
|
|
|
|
.send({ description: 'foo' });
|
|
|
|
|
|
|
|
expect(status).toBe(400);
|
2023-09-20 13:16:33 +02:00
|
|
|
expect(body).toEqual(errorStub.badRequest());
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
|
|
|
it('should update shared link', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.patch(`/shared-link/${sharedLink.id}`)
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`)
|
|
|
|
.send({ description: 'foo' });
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
expect(body).toEqual(
|
|
|
|
expect.objectContaining({ type: SharedLinkType.ALBUM, userId: user1.userId, description: 'foo' }),
|
|
|
|
);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
|
|
|
|
describe('DELETE /shared-link/:id', () => {
|
|
|
|
it('should require authentication', async () => {
|
|
|
|
const { status, body } = await request(server).delete(`/shared-link/${sharedLink.id}`);
|
|
|
|
|
|
|
|
expect(status).toBe(401);
|
|
|
|
expect(body).toEqual(errorStub.unauthorized);
|
|
|
|
});
|
|
|
|
|
|
|
|
it('should fail if invalid link', async () => {
|
|
|
|
const { status, body } = await request(server)
|
|
|
|
.delete(`/shared-link/${uuidStub.notFound}`)
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`);
|
|
|
|
|
|
|
|
expect(status).toBe(400);
|
2023-09-20 13:16:33 +02:00
|
|
|
expect(body).toEqual(errorStub.badRequest());
|
2023-09-11 17:56:38 +02:00
|
|
|
});
|
|
|
|
|
2023-11-15 02:08:22 +01:00
|
|
|
it('should delete a shared link', async () => {
|
2023-09-11 17:56:38 +02:00
|
|
|
const { status } = await request(server)
|
|
|
|
.delete(`/shared-link/${sharedLink.id}`)
|
|
|
|
.set('Authorization', `Bearer ${user1.accessToken}`);
|
|
|
|
|
|
|
|
expect(status).toBe(200);
|
|
|
|
});
|
|
|
|
});
|
|
|
|
});
|